Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.7% | — | Debian LinuxCanonical Ubuntu LinuxLibxcursorRedhat Ansible Tower+3 | 1/8/2018 | 17/6/2026 | _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. | |
| Modificada | Alta (8.8) | 3.8% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression. | |
| Modificada | Alta (8.8) | 3.8% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite. | |
| Modificada | Media (6.5) | 3.7% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames. | |
| Modificada | Media (6.5) | 3.3% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash). | |
| Modificada | Alta (7.2) | 1.7% | — | Redhat Ansible TowerRedhat Cloudforms | 27/7/2018 | 17/6/2026 | A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access to the upstream playbook source repository could create a Trojan playbook that, when executed by… | |
| Modificada | Media (6.5) | 3.1% | — | Freedesktop PopplerCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+4 | 25/7/2018 | 17/6/2026 | Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file. | |
| Modificada | Crítica (9.8) | 4.2% | — | Gnome LibsoupCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+5 | 5/7/2018 | 17/6/2026 | The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. | |
| Modificada | Alta (7.5) | 4.9% | — | PythonDebian LinuxRedhat Ansible TowerRedhat Enterprise Linux Desktop+4 | 19/6/2018 | 17/6/2026 | python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service. | |
| Modificada | Alta (7.5) | 5.0% | — | PythonFedoraproject FedoraCanonical Ubuntu LinuxRedhat Ansible Tower+4 | 18/6/2018 | 17/6/2026 | python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service. | |
| Modificada | Media (4.7) | 0.89% | — | Gnupg LibgcryptCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+4 | 13/6/2018 | 17/6/2026 | Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an… | |
| Modificada | Media (5.5) | 1.9% | — | Freedesktop PopplerCanonical Ubuntu LinuxRedhat Ansible TowerRedhat Enterprise Linux Desktop+3 | 10/5/2018 | 17/6/2026 | The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops. | |
| Modificada | Media (6.5) | 2.4% | — | Freedesktop PopplerCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+3 | 6/5/2018 | 17/6/2026 | There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected. | |
| Modificada | Media (6.5) | 2.2% | — | Gnome LibgxpsRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 6/5/2018 | 17/6/2026 | There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Media (6.5) | 2.2% | — | Gnome LibgxpsRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 4/5/2018 | 17/6/2026 | There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Alta (8.8) | 2.5% | — | Redhat Ansible TowerRedhat Cloudforms | 2/5/2018 | 17/6/2026 | Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server. | |
| Modificada | Alta (7.2) | 2.0% | — | Redhat Ansible TowerRedhat Cloudforms | 2/5/2018 | 17/6/2026 | Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the… |